Skip to content

ci: call the org leak-scan workflow - #6

Merged
joepetjr merged 4 commits into
mainfrom
ci/leak-scan
Aug 9, 2026
Merged

joepetjr merged 4 commits into
mainfrom
ci/leak-scan

Conversation

@joepetjr

@joepetjr joepetjr commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Calls the org's shared leak-scan workflow, which checks that this repo publishes
its own work and nothing else: no other project's name from this org, no client's
name, no layout convention from the private monorepo, and no absolute path from an
authoring machine.

The whole change is one uses: line. There is no pattern list here and no setting
that names this repo — the scanner derives that from ${{ github.repository }}, so
there is nothing in this file to keep in sync and nothing that can go stale.

Depends on #4 and #5; this PR's check stays red until
those land, then passes on re-run.

Test plan

A fresh clone of this repo was scanned with the same rule set before this was
wired up — no findings, in the worktree or anywhere in history. The gate is
therefore green from the start rather than being wired up over a known failure.

Verified clean against this rule set before wiring: a fresh clone scanned with no
findings in the worktree or in history.
…ADME

The rule table names what each rule catches, the lookahead explanation
names the sibling repo it once missed, and the allowlist example shows a
realistic match string. A doc that cannot say any of that documents
nothing. Four entries, each scoped to rule+path+match per the contract
this repo's own tests enforce.
@joepetjr
joepetjr merged commit 7fd7170 into main Aug 9, 2026
3 checks passed
@joepetjr
joepetjr deleted the ci/leak-scan branch August 9, 2026 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant